XDR-Analyst · domain
Identity Threat Detection And Response
Practise Certified XDR Analyst (XDR-Analyst) Identity Threat Detection And Response practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Identity Threat Detection And Response questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Identity Threat Detection And Response
Identity Threat Detection And Response questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Identity Threat Detection And Response exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Identity Threat Detection And Response questions (44)
Click any question to see the full explanation, or start a practice session above.
An analyst needs to create a BIOC (Behavioral Indicator of Compromise) rule to detect suspicious use of 'whoami' execution by an authenticated domain user. Which data source should the rule evaluate?
Easy2An analyst is configuring a BIOC rule to detect credential dumping via LSASS memory access. Which event characteristic must be monitored within the endpoint telemetry criteria?
Medium3What is the primary purpose of integrating Microsoft Entra ID (formerly Azure AD) logs into Cortex XDR?
Easy4An analyst notices that a service account is generating alerts for anomalous login locations. Upon review, the account is used by an automated batch script running from a newly provisioned server. How should the analyst resolve this alert while maintaining security best practices?
Medium5An administrator is setting up User Risk Scoring within Cortex XDR. They notice that certain service accounts with high volumes of automated authentications are skewing the risk calculations. How should the administrator handle these service accounts in Cortex XDR to prevent false-positive risk elevations?
Medium6An attacker compromises a domain user account and attempts to enumerate domain admins using native Windows utilities (e.g., 'net group "Domain Admins" /domain'). Which Cortex XDR detection mechanism is specifically designed to catch such reconnaissance behaviors without relying solely on static signatures?
Hard7An administrator is reviewing compromised credentials in Cortex XDR. Where should they navigate to inspect identity analytics alerts specifically generated by user behavior analytics (UBA)?
Easy8An enterprise is facing credential stuffing attacks targeting its cloud and on-premises applications. Which TWO detection or mitigation strategies within Cortex XDR and integrated tools help address this threat?
Hard9Which TWO log sources are commonly ingested into Cortex XDR to support Identity Threat Detection and Response (ITDR)?
Easy10Which TWO metrics or components are typically included in a user's risk score calculation within Cortex XDR's identity analytics?
Easy11What role does the Cortex XDR Broker VM play regarding Active Directory and ITDR log collection?
Easy12An analyst is reviewing an identity incident where an attacker performed a Kerberoasting attack. Which log source ingested by Cortex XDR is most critical for detecting requests for service tickets against high-privilege service principal names (SPNs)?
Medium13An organization wants to ensure that all administrative logon sessions are closely monitored for anomalous behaviors in Cortex XDR. Where should the administrator configure custom behavioral alert thresholds for privileged users?
Medium14An organization experiences a Golden Ticket attack. How does Cortex XDR's identity analytics engine typically detect this type of Kerberos ticket manipulation?
Hard15When investigating an identity-based alert in Cortex XDR, what information does the User View provide to the analyst?
Easy16An analyst is reviewing an XQL query designed to hunt for suspicious account creation followed by immediate group membership escalation in Active Directory. Which XQL construct is used to join Active Directory event datasets based on a common security identifier (SID)?
Hard17Which TWO data sources can Cortex XDR leverage to build comprehensive user identity behavior profiles for ITDR? (Choose two)
Easy18What is the primary benefit of using Cortex XDR's identity correlation engine when triaging incidents?
Easy19Which TWO methods can an administrator use to ingest Active Directory logs into Cortex XDR?
Easy20Which THREE features of Cortex XDR assist an analyst in conducting a deep-dive forensic investigation into an identity-based alert?
Medium21An analyst needs to verify whether Active Directory audit policies are correctly configured to supply Cortex XDR with the necessary event logs for Identity Threat Detection and Response. Which Windows Event ID range contains the core authentication and credential validation events required by Cortex XDR ITDR?
Easy22An analyst is investigating a suspected pass-the-ticket attack where an attacker injects a stolen Kerberos ticket into memory. Which endpoint telemetry data collected by the Cortex XDR Agent helps identify abnormal process behavior related to ticket injection tools (such as Mimikatz 'kerberos::ptt')
Hard23An analyst is investigating a suspicious user account that accessed sensitive internal shares outside of normal business hours. Which Cortex XDR feature enables the analyst to review all actions taken by this user across endpoints and cloud services in a chronological timeline?
Medium24Which log source is essential for Cortex XDR to track successful and failed interactive logon events on Windows workstations for ITDR analysis?
Easy25An analyst is investigating a compromised user account in Cortex XDR and wants to review identity-based alerts generated by Active Directory monitoring. Which specific view in the Cortex XDR management console provides a consolidated timeline of identity events and authentication anomalies for a specific user?
Easy26An administrator wants to configure automated response actions for high-severity ITDR alerts indicating active credential compromise. Which Cortex XDR feature allows automated actions such as disabling the compromised user account in Active Directory?
Hard27Where can an administrator view the overall identity risk posture score across all users within the Cortex XDR management console?
Easy28Which THREE key components or features in Cortex XDR contribute directly to identifying and investigating compromised user credentials?
Medium29An ITDR rule in Cortex XDR triggers due to impossible travel detected for a user account. Upon investigation, the analyst discovers the source IP belongs to a corporate VPN egress node. How should the analyst prevent future false positives for this known infrastructure?
Hard30While reviewing an incident involving suspicious lateral movement, an analyst notices that an adversary utilized compromised service account credentials. The analyst wants to use Cortex XDR response actions to immediately contain the threat without shutting down the entire domain controller. Which ITDR-related action can be executed directly from the Cortex XDR console for a compromised user account?
Medium31Which THREE indicators collected by Cortex XDR endpoint agents are crucial for identifying post-exploitation credential harvesting activities on a host?
Medium32Which THREE actions can be taken directly or via orchestration within Cortex XDR when responding to an active identity-based attack?
Medium33When deploying and troubleshooting the integration between Cortex XDR and Active Directory for ITDR, which TWO steps or configurations are critical to ensure successful telemetry collection? (Choose two)
Hard34You are configuring integration between Cortex XDR and an external Identity Provider (IdP) to ingest user authentication logs for ITDR. Which component is primarily responsible for securely forwarding these IdP telemetry logs to the Cortex XDR data lake?
Medium35An organization wants to enrich Cortex XDR alerts with Active Directory context. Which component must be properly configured and running to collect user and group metadata for ITDR correlation?
Medium36An organization notices an increase in adversary reconnaissance using BloodHound to map Active Directory permissions. Which data telemetry in Cortex XDR can help detect the enumeration queries associated with this activity?
Medium37An organization notices an increase in credential dumping attacks against local Active Directory environments. They want to configure Cortex XDR Identity Analytics to trigger high-severity alerts when abnormal Kerberos ticket requests (such as potential Silver or Golden ticket activities) are detected. Where should the analyst enable or tune these specific identity behavior analytics rules?
Hard38Which THREE key identity-based threat behaviors are typically detected and flagged by Cortex XDR Identity Analytics? (Choose three)
Medium39Which THREE configuration steps are required to ensure Cortex XDR successfully correlates endpoint events with Active Directory user identities?
Medium40Which TWO features in Cortex XDR assist analysts in communicating identity threat findings to stakeholders or compliance auditors?
Easy41A security analyst suspects an account compromise after noticing multiple rapid logins from geographically distant IP addresses within minutes. Which Cortex XDR feature automatically aggregates these related anomalous authentication indicators into a single incident?
Medium42When reviewing identity analytics alerts in Cortex XDR, which THREE behavioral anomalies are typically flagged by the UBA engine as potential indicators of a compromised account?
Hard43An analyst is investigating an incident where an attacker leveraged compromised credentials to establish persistence via Active Directory object manipulation. Which TWO Active Directory event logs or actions captured by ITDR monitoring should the analyst examine?
Hard44Which TWO types of user accounts are critical to monitor closely for privilege abuse and anomalous behavior within an ITDR program?
EasyOther domains
All XDR-Analyst exam domains
Frequently asked questions
- What does the Identity Threat Detection And Response domain cover on the XDR-Analyst exam?
- Identity Threat Detection And Response questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 44 Identity Threat Detection And Response questions in the XDR-Analyst question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Identity Threat Detection And Response questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.